100profile quality
Cylus provides specialized cybersecurity solutions and a real-time asset visibility platform for rail operators to ensure service availability and safety in operational technology systems.
Value proposition
"Secure Every System. Keep Rail in Motion." A unified cybersecurity and asset visibility platform purpose-built for railway companies to continuously monitor, detect, and protect every layer of operational technology (OT) across infrastructure, rolling stock, control centers, and stations.
Where it wins
- Rail-Specific Visibility: Replaces generic OT dashboards with CylusOne, which maps the operational reality of rail domains including signaling, SCADA, PIS, CCTV, and dispatch systems [1].
- Certified Compliance: The first rail cybersecurity solution certified to IEC 62443-4-2 at Security Level 3 (SL 3), directly addressing global regulatory requirements [1].
- Unified Threat Management: Provides actionable, rail-specific insights for vulnerability management and real-time threat detection across wayside and onboard systems [1].
Credibility: IEC 62443-4-1 and 4-2 certifications validate the platform's technical rigor for critical rail infrastructure [1].
Business model
- Product-Led Security Platform: Sells CylusOne as a unified software layer that abstracts the complexity of diverse rail OT protocols and assets [1].
- Certification-Driven Differentiation: Leverages rare IEC 62443-4-2 SL3 certification to command premium positioning and reduce buyer risk [1].
- Ecosystem Integration: Scales distribution by partnering with hardware vendors (Belden) and OEMs (Alstom) to embed CylusOne into existing rail procurement cycles [1][2].
- Compliance as a Service: Addresses the regulatory burden on rail operators by providing pre-validated tools for IEC 62443 and emerging standards like EN 50126/8/9 [1].
Competitive landscape
- Generic OT Security Vendors: Competitors like Nozomi or Claroty offer broad OT visibility but lack rail-specific certifications and deep protocol support [1].
- Rail OEM In-House Security: Traditional OEMs (e.g., Siemens, Thales) often bundle basic security, but Cylus offers specialized, certified third-party depth [1].
- IT-Centric Security Providers: Vendors like Palo Alto or Fortinet focus on IT networks, missing the OT-specific threat detection and asset mapping Cylus provides [1].
- Differentiators: Cylus wins on rail-specificity, IEC 62443-4-2 SL3 certification, and deep OEM/hardware partnerships (Alstom, Belden) [1][2].
- Threats: Large generic OT vendors may develop rail-specific modules, or OEMs may build superior in-house security capabilities [1].
Market pains
- Fragmented OT Visibility: Rail operators struggle to see and manage security across diverse, siloed systems (signaling, SCADA, rolling stock) [1].
- Regulatory Complexity: Increasing global regulations (IEC 62443, EU Cyber Resilience Act) create compliance burdens and audit risks [1].
- Generic Security Tools: Standard IT/OT security solutions lack rail-specific protocols and context, leading to blind spots and false positives [1].
- Cyber-Physical Threats: Growing motivation of threat actors to target rail infrastructure, causing operational disruptions and safety risks (e.g., PKP Poland attack) [1].
- Lack of In-House Expertise: Rail OEMs and operators often lack dedicated cybersecurity teams, relying on external partners for protection [1].
Strategic implications
Cylus has successfully carved a defensible niche by combining deep rail specificity with rare regulatory certification. The Alstom and Belden partnerships are critical wedges, embedding Cylus into the rail supply chain before competitors can replicate the integrations. The main risk is the 'certification moat' eroding if generic OT vendors achieve similar IEC 62443-4-2 SL3 status. The next signal to watch is Cylus's expansion beyond passenger rail into freight or global markets outside Europe, and whether they can productize their advisory services into a scalable subscription layer.
Improvement suggestions
Cylus should aggressively market its IEC 62443-4-2 SL3 certification as a mandatory procurement requirement for rail operators, creating a compliance-driven demand funnel. Expand the Belden and Alstom partnerships into co-branded 'Cylus for [Partner]' solutions to accelerate distribution and reduce direct sales friction. Develop a self-service or low-touch onboarding path for smaller transit agencies to capture the long-tail market without heavy professional services costs. Publish more case studies and threat intelligence reports specific to rail incidents (like PKP Poland) to position Cylus as the thought leader in rail cyber resilience.
- PEPperPRINT GmbHfounded